Skip to content

Commit

Permalink
Restrict vtpm access to neede directories only
Browse files Browse the repository at this point in the history
Restrict vtpm access to needed directories only, it
doesn't need access to all of the /persist and /run,
just /persist/swtpm and /run/swtpm.

Signed-off-by: Shahriyar Jalayeri <[email protected]>
  • Loading branch information
shjala committed Sep 3, 2024
1 parent 9f55aac commit 58830f0
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions pkg/vtpm/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ config:
additionalGids: [100]
binds:
- /dev:/dev
- /run:/run
- /persist:/persist
- /run/swtpm:/run/swtpm
- /persist/swtpm:/persist/swtpm
devices:
- path: all
type: a

0 comments on commit 58830f0

Please sign in to comment.